Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, from the New York Times:

Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency. The N.S.A. wrote the standard and aggressively pushed it on the international group, privately calling the effort “a challenge in finesse.”

“Eventually, N.S.A. became the sole editor,” the memo says.



The presentation on the vulnerability, from the two Microsoft employees, for those interested: http://rump2007.cr.yp.to/15-shumow.pdf

Amusingly, from the PDF:

> WHAT WE ARE NOT SAYING:

> NIST intentionally put a back door in this PRNG

:)




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: